Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2022:1479-1

Опубликовано: 29 апр. 2022
Источник: suse-cvrf

Описание

Security update for jasper

This update for jasper fixes the following issues:

  • CVE-2021-3467: Fixed NULL pointer deref in jp2_decode() (bsc#1184757).
  • CVE-2021-3443: Fixed NULL pointer deref in jp2_decode() (bsc#1184798).
  • CVE-2021-26927: Fixed NULL pointer deref in jp2_decode() (bsc#1182104).
  • CVE-2021-26926: Fixed an out of bounds read in jp2_decode() (bsc#1182105).

Список пакетов

SUSE Linux Enterprise Module for Basesystem 15 SP3
libjasper4-2.0.14-150000.3.25.1
SUSE Linux Enterprise Module for Desktop Applications 15 SP3
libjasper-devel-2.0.14-150000.3.25.1
SUSE Linux Enterprise Real Time 15 SP2
libjasper-devel-2.0.14-150000.3.25.1
libjasper4-2.0.14-150000.3.25.1
openSUSE Leap 15.3
jasper-2.0.14-150000.3.25.1
libjasper-devel-2.0.14-150000.3.25.1
libjasper4-2.0.14-150000.3.25.1
libjasper4-32bit-2.0.14-150000.3.25.1
openSUSE Leap 15.4
jasper-2.0.14-150000.3.25.1
libjasper-devel-2.0.14-150000.3.25.1
libjasper4-2.0.14-150000.3.25.1
libjasper4-32bit-2.0.14-150000.3.25.1

Описание

A flaw was found in jasper before 2.0.25. An out of bounds read issue was found in jp2_decode function whic may lead to disclosure of information or program crash.


Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15 SP3:libjasper4-2.0.14-150000.3.25.1
SUSE Linux Enterprise Module for Desktop Applications 15 SP3:libjasper-devel-2.0.14-150000.3.25.1
SUSE Linux Enterprise Real Time 15 SP2:libjasper-devel-2.0.14-150000.3.25.1
SUSE Linux Enterprise Real Time 15 SP2:libjasper4-2.0.14-150000.3.25.1

Ссылки

Описание

A flaw was found in jasper before 2.0.25. A null pointer dereference in jp2_decode in jp2_dec.c may lead to program crash and denial of service.


Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15 SP3:libjasper4-2.0.14-150000.3.25.1
SUSE Linux Enterprise Module for Desktop Applications 15 SP3:libjasper-devel-2.0.14-150000.3.25.1
SUSE Linux Enterprise Real Time 15 SP2:libjasper-devel-2.0.14-150000.3.25.1
SUSE Linux Enterprise Real Time 15 SP2:libjasper4-2.0.14-150000.3.25.1

Ссылки

Описание

A NULL pointer dereference flaw was found in the way Jasper versions before 2.0.27 handled component references in the JP2 image format decoder. A specially crafted JP2 image file could cause an application using the Jasper library to crash when opened.


Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15 SP3:libjasper4-2.0.14-150000.3.25.1
SUSE Linux Enterprise Module for Desktop Applications 15 SP3:libjasper-devel-2.0.14-150000.3.25.1
SUSE Linux Enterprise Real Time 15 SP2:libjasper-devel-2.0.14-150000.3.25.1
SUSE Linux Enterprise Real Time 15 SP2:libjasper4-2.0.14-150000.3.25.1

Ссылки

Описание

A NULL pointer dereference flaw was found in the way Jasper versions before 2.0.26 handled component references in CDEF box in the JP2 image format decoder. A specially crafted JP2 image file could cause an application using the Jasper library to crash when opened.


Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15 SP3:libjasper4-2.0.14-150000.3.25.1
SUSE Linux Enterprise Module for Desktop Applications 15 SP3:libjasper-devel-2.0.14-150000.3.25.1
SUSE Linux Enterprise Real Time 15 SP2:libjasper-devel-2.0.14-150000.3.25.1
SUSE Linux Enterprise Real Time 15 SP2:libjasper4-2.0.14-150000.3.25.1

Ссылки
Уязвимость SUSE-SU-2022:1479-1